First published: Wed Feb 02 2011(Updated: )
Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vulnerability than CVE-2010-1427.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
MODx CMS Evolution | <=1.0.4 | |
MODx CMS Evolution | =0.9.0 | |
MODx CMS Evolution | =0.9.1 | |
MODx CMS Evolution | =0.9.2.1 | |
MODx CMS Evolution | =0.9.5 | |
MODx CMS Evolution | =0.9.6 | |
MODx CMS Evolution | =0.9.6.1 | |
MODx CMS Evolution | =0.9.6.1-p1 | |
MODx CMS Evolution | =0.9.6.2 | |
MODx CMS Evolution | =1.0.2 | |
MODx CMS Evolution | =1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3930 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2010-3930, upgrade to MODx Evolution version 1.0.5 or later to mitigate the directory traversal vulnerability.
CVE-2010-3930 affects MODx Evolution versions 1.0.4 and earlier, as well as several specific earlier minor versions.
An attacker exploiting CVE-2010-3930 can read arbitrary files on the server, potentially leading to sensitive data exposure.
CVE-2010-3930 is mentioned as a different vulnerability than CVE-2010-1427 in relation to the same software.